{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anetappactive_iq_unified_manager-vmware_vsphere/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*","cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h300s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h500s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h700s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h410s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h410c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2024-2961"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GNU C Library"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","linux","vulnerability"],"_cs_type":"advisory","_cs_vendors":["GNU"],"content_html":"\u003cp\u003eThe BSI has reported a vulnerability within the GNU C Library (glibc), identified as CVE-2024-2961. This flaw permits a local attacker to trigger a Denial of Service (DoS) condition on affected Linux systems. The vulnerability stems from improper handling of specific inputs by the library during runtime, which can cause applications linked against the compromised version of glibc to crash or become unstable. Given that glibc is a fundamental component of most Linux distributions, this vulnerability impacts a wide range of services and applications that rely on its core functions for memory management, string manipulation, and system calls. Defenders should prioritize patching the glibc packages provided by their distribution maintainers to mitigate the risk of local service disruption.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in the disruption of availability for critical services and applications running on the affected Linux host. This can lead to service outages, potential data loss during unexpected crashes, and operational downtime. Because the vulnerability requires local access, it is particularly relevant in multi-user environments or systems where untrusted local users have the ability to execute code.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and system administration teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the GNU C Library (glibc) packages via the system package manager immediately upon the release of patched versions by the OS distribution vendor.\u003c/li\u003e\n\u003cli\u003eReview system logs for frequent, unexpected process crashes (e.g., segment faults or core dumps) for services that may be triggering the vulnerable code paths.\u003c/li\u003e\n\u003cli\u003eAudit multi-user Linux environments to restrict execution permissions for untrusted users to minimize the impact of local exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T11:35:50Z","date_published":"2026-08-11T11:35:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-glibc-dos/","summary":"A local attacker can exploit a vulnerability in the GNU C Library (glibc) to cause application crashes or service instability, resulting in a Denial of Service.","title":"Denial of Service Vulnerability in GNU C Library","url":"https://feed.craftedsignal.io/briefs/2026-08-glibc-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:Vmware_vsphere:*:*","version":"https://jsonfeed.org/version/1.1"}